Security & compliance
Every environment ships with two separate payer plans, because isolation that cannot be demonstrated is not isolation. Ask us to reach one plan’s data with the other’s credentials, live, on the call — and to show what the attempt left in the audit record.
Who someone is, what role they hold and which plan they belong to are resolved from your identity provider — never from anything the request itself claims. SSO and OIDC, per tenant, on a certified relying-party library; no shared or standing credentials.
Your own reference data — eligibility, plan design, contracted fees, accumulators, payment and authorisation history — is held separately from the industry content every plan shares. Ownership is checked where a fact is used, not only at the front door.
PHI
A report that answers “who read this member’s record” from data nobody captured reads as nobody looked. So the record is written at the moment of the read, on every route that can return member information.
It covers every alternate form of the same request, so no path is a blind spot, and the entry is committed before the response leaves — whether the request succeeded or failed.
The AI boundary
One audited boundary is the only place in the platform that can reach an AI provider. Everything else — editing, pricing, the trace, governance — runs with no provider connected at all.
Identifiers hide inside sentences the platform itself wrote — a member number in the middle of an explanation. Removal is by content, not by field name, and the disclosure record names what was removed rather than asserting that nothing identifying left.
A plain-language explanation is checked back against the decision and the arithmetic before a reviewer ever sees it: every figure by value and by what the sentence says it is, and no sentence may promise an outcome the claim did not receive.
Which provider a deployment is using, what it is permitted to see, what is therefore enabled, and what has left the system — on one screen in the product, for your compliance officer to read rather than for us to describe.
Deployment posture
Anonymous access defaults to closed in production and the profile is logged at boot. On a closed instance no read answers without a session, and an unauthenticated submission needs a channel credential that binds it to exactly one tenant.
Both postures are verified independently before every release — including a deployment started with a deliberately failing data source, to prove a claim stops rather than adjudicating on facts nobody can vouch for.
Data integrity
Assurance
Every part of this platform has been through independent adversarial review, and every confirmed finding is recorded with the window in which the control did not hold — not only the end state in which it does. Your risk committee is entitled to the second statement, and it is the harder one to make.
A known-limitations register ships with the product. Your diligence team gets it on day one, so nothing in it becomes a surprise found later by your auditor — or by a regulator.
An architecture and data-flow document, the control set mapped to each commitment on this page, the known-limitations register, the disclosure history, and a live session in which any control on this page is demonstrated on request rather than attested on paper.
A control that refuses because it works and a control that refuses because it is broken look identical from outside. We show you both sides on a live system, so you are judging evidence rather than a claim.
When something was wrong, we state what was reachable and for how long — the fact your breach analysis needs and the one vendors usually leave out.
Bring your privacy officer to the same call as your claims lead. The isolation demonstration takes ten minutes and it is the part of the demo people remember.